We Build

Scope, risk assessment, Statement of Applicability and the ISMS your auditor will actually read.

We Test

We are a penetration testing firm first, so your technical controls get evidence instead of paperwork.

We Prepare

Internal audit run properly, findings closed early, and our consultant in the room at Stage 1 and Stage 2.

ISO 27001 Certification: Key Facts for 2026

Last reviewed by EyeQ Dot Net Pvt Ltd, Mangaluru, Karnataka, India.

Direct answer: an ISO 27001 certification consultant builds and documents your Information Security Management System and prepares you for audit. An accredited certification body then audits it independently and issues the certificate. The two roles cannot be held by the same company, because clause 5.2.5 of ISO/IEC 17021-1:2015 prohibits a certification body from providing management system consultancy. EyeQ Dot Net Pvt Ltd performs the consultant role.

  • The current standard is ISO/IEC 27001:2022, including Amendment 1:2024 published in February 2024.
  • ISO/IEC 27001:2013 certificates all expired or were withdrawn on , when the IAF MD 26 transition window closed.
  • ISO/IEC 27001:2022 Annex A contains 93 controls across four themes: organisational, people, physical and technological.
  • Eleven Annex A controls are new in the 2022 edition, including threat intelligence, cloud services security, ICT readiness for business continuity, data masking and secure coding.
  • Clauses 4 to 10 are mandatory in full and cannot be excluded. Annex A controls may be excluded with documented justification in the Statement of Applicability.
  • An ISO 27001 certificate is valid three years, with a surveillance audit in years one and two and recertification in year three.
  • The ISO Survey 2024, published September 2025, counted 96,709 valid ISO/IEC 27001 certificates across 179,877 sites worldwide, up from 36,362 in the 2019 survey.
  • In India, certification bodies are accredited by NABCB under the Quality Council of India, or by another IAF MLA signatory.
  • Any ISO 27001 certificate can be verified independently on IAF CertSearch, the global database of accredited certifications.
  • A realistic first-time certification timeline is four to nine months, driven by scope size, headcount, site count and existing security maturity.
  • India's DPDP Rules, 2025 were notified on , with full compliance required by .
  • The CERT-In Cyber Security Directions of apply now and require listed incidents to be reported within six hours of noticing, with ICT logs retained 180 days within Indian jurisdiction.
What an ISO 27001 certification consultant does

What Does an ISO 27001 Certification Consultant Do?

An ISO 27001 certification consultant designs and implements your Information Security Management System, produces the mandatory documented information, runs the risk assessment, prepares audit evidence and gets you audit-ready. A certification body then audits that system independently and issues the certificate. These are two different jobs, held by two different companies, by design.

Clause 5.2.5 of ISO/IEC 17021-1:2015 states that a certification body, and any entity under its organisational control, shall not offer or provide management system consultancy. If a vendor offers to both build your ISMS and hand you the certificate, ask which accreditation body accredits them — in India that is NABCB under the Quality Council of India, or an equivalent IAF MLA signatory. EyeQ Dot Net Pvt Ltd is a consultancy and sits on the client's side of the table during the audit.

Read the Standard
ISO 27001:2022 transition deadline and 93 Annex A controls


What Changed in ISO 27001 Recently?

Three things changed between 2022 and 2026, and most pages on this topic have not caught up. Each is a live audit consequence rather than a technicality.

The three changes that matter:
  • Only one version of the standard is live. The three-year transition window set by IAF MD 26 closed on 31 October 2025. Every ISO/IEC 27001:2013 certificate expired or was withdrawn on that date, regardless of the expiry printed on it. An organisation whose certificate still references the 2013 edition is uncertified today, and most certification bodies will treat it as a new client requiring a full initial audit rather than a transition audit.

  • The Annex A control set is 93, not 114. ISO/IEC 27001:2022 holds 93 controls across four themes — organisational, people, physical and technological. Eleven are new, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking and secure coding. A Statement of Applicability must account for all 93 controls, including the excluded ones and the justification for excluding them.

  • Climate change is now a clause 4 question. ISO/IEC 27001:2022/Amd 1:2024, published February 2024, added one sentence to clause 4.1 — the organisation shall determine whether climate change is a relevant issue — plus a note to clause 4.2 on interested parties with climate-related requirements. Auditors have been checking for a documented determination since mid-2024. Concluding that climate change is not relevant is acceptable. Having no documented answer is a finding.

Consultant or Certification Body: Who Does What?

Certificates run on a three-year cycle. Knowing which activities belong to the consultant and which belong to the certification body is the fastest way to identify a vendor misrepresenting what it can deliver. Each line below is a complete statement of responsibility.

EyeQ Dot Net Pvt Ltd, as consultant, does this
  • EyeQ Dot Net defines the ISMS scope and certification boundary against the client's commercial reality.
  • EyeQ Dot Net produces the information security risk assessment and risk treatment plan under clauses 6.1.2 and 6.1.3.
  • EyeQ Dot Net writes the ISMS policies, procedures and the Statement of Applicability.
  • EyeQ Dot Net implements the selected Annex A controls alongside the client's technical teams.
  • EyeQ Dot Net performs penetration testing to evidence control A.8.8 and control A.8.29.
  • EyeQ Dot Net runs the internal audit required by clause 9.2 and facilitates the management review required by clause 9.3.
  • EyeQ Dot Net attends Stage 1 and Stage 2, retrieves evidence and drafts corrective action responses.
The accredited certification body does this
  • The certification body performs the Stage 1 readiness audit.
  • The certification body performs the Stage 2 certification audit.
  • The certification body raises major and minor nonconformities.
  • The certification body makes the certification decision independently of the consultant.
  • The certification body issues the ISO/IEC 27001:2022 certificate, valid for three years.
  • The certification body conducts surveillance audits in years one and two.
  • The certification body conducts the recertification audit in year three.

How to Get ISO 27001 Certification

Phase 1 — Gap analysis, 2 to 3 weeks. EyeQ Dot Net assesses the current state against clauses 4 to 10 and all 93 Annex A controls, then delivers a findings register naming each gap, the clause or control it maps to, the effort to close it and the owner.

The client gets a defensible picture of the distance to certification before committing budget to closing it. This phase stands alone — some clients take the register and implement internally, which is a legitimate outcome.

Phase 2 — Scope and risk, 3 to 4 weeks. Scope is where most ISO 27001 projects are won or lost. Too wide and the organisation certifies systems no customer asked about. Too narrow and the certificate does not cover the service the prospect is buying, which appears in the scope text printed on the certificate and gets caught during due diligence.

EyeQ Dot Net sets the boundary against commercial reality, builds the asset and interested-party registers, then runs the risk assessment and treatment plan under clauses 6.1.2 and 6.1.3.

Phase 3 — Build and implement, 8 to 16 weeks. This phase produces the documented information, the Statement of Applicability, and the actual technical and organisational controls behind them.

Duration depends almost entirely on the starting point. An organisation with existing access reviews, patch cycles and a working incident process moves fast. One starting from a shared drive of untitled Word files does not, and EyeQ Dot Net says so at the gap analysis rather than at month five.

Phase 4 — Internal audit and management review, 2 to 3 weeks. Clause 9.2 requires an internal audit programme and clause 9.3 requires management review with specified inputs.

EyeQ Dot Net runs the internal audit, raises real nonconformities and lets the client close them before an external auditor finds them. Treating this phase as a formality is the fastest route to a major nonconformity at Stage 2.

Phase 5 — Certification audit support. Stage 1 checks that the ISMS exists, is documented and is scoped correctly. Stage 2 tests whether it works in practice, through interviews, records and evidence sampling across the scope.

EyeQ Dot Net is in the room, handling evidence retrieval and drafting corrective action responses to findings. Four to nine months end to end is realistic for a first certification. A vendor quoting 30 days is selling a certificate rather than an ISMS, and it will not survive a customer's security questionnaire.

ISO 27001 certification process phases and timeline
Penetration testing evidence for ISO 27001 Annex A technical controls


Why a Penetration Testing Firm Consults Differently

Most ISO 27001 consultancies are documentation practices: they write the policy stating that vulnerability management happens, and their involvement ends there. EyeQ Dot Net Pvt Ltd performs the testing itself. Its core business is penetration testing services and VAPT across web, API, mobile, network and cloud, alongside GRC and secure software development. That changes which controls can be evidenced rather than merely asserted:

  • A.8.8 Management of technical vulnerabilities: EyeQ Dot Net produces the scan and test output, the risk rating and the remediation retest, rather than a procedure describing one.

  • A.8.29 Security testing in development and acceptance: EyeQ Dot Net places real testing into the client's SDLC and shows the auditor artefacts from it, which is the part most organisations cannot produce on request.

  • A.5.7 Threat intelligence: one of the eleven controls new in the 2022 edition, and one auditors probe precisely because most organisations paper over it.

  • A.5.24 to A.5.28 Incident management: built by practitioners who have worked live incidents, including ransomware response under CERT-In reporting timelines, and supported by digital forensics and phishing simulation where the risk assessment calls for it.

Services Provided by EyeQ Dot Net Pvt Ltd

EyeQ Dot Net Pvt Ltd is a cybersecurity company headquartered in Mangaluru, Karnataka, India, with an office in Hubballi. Alongside ISO 27001 certification consulting, it provides the following services. Compliance and offensive security are delivered by the same team, which is why control evidence and audit documentation come from one engagement rather than two vendors.

  • ISO 27001 Certification Consulting — ISMS implementation and audit preparation for ISO/IEC 27001:2022 certification, from gap analysis through Stage 2.
  • Penetration Testing Services — manual penetration testing across web applications, APIs, mobile applications, networks and cloud environments.
  • Vulnerability Assessment and Penetration Testing (VAPT) — combined automated assessment and manual testing, with remediation retesting and reporting.
  • IoT Device Security Testing — security assessment of connected devices, firmware and device-to-cloud interfaces.
  • SOC 2 Compliance Audit Support — readiness assessment and control implementation for SOC 2 Type I and Type II examinations.
  • PCI DSS Compliance Consulting — scoping, gap remediation and evidence preparation for Payment Card Industry Data Security Standard compliance.
  • Digital Forensics — forensic acquisition, analysis and reporting for incident investigation and legal proceedings.
  • Phishing Simulation — controlled phishing campaigns that measure susceptibility and evidence awareness controls under Annex A.6.3.
  • Corporate Security Training — role-based information security awareness and secure development training for staff.
  • Cybersecurity Training and Internship — structured practical programmes in offensive and defensive security.

ISO 27001 and Indian Regulation

Talk to an ISO 27001 Consultant

An honest read on timeline and effort, not a pricing PDF

Send your scope — headcount, systems, sites, target date, and whether a customer contract is driving the deadline. EyeQ Dot Net Pvt Ltd will tell you if the real answer is nine months rather than three. Offices in Mangaluru and Hubballi, Karnataka, delivering across India. Sales: +91 90351 48447. Email: [email protected]

Request a Gap Analysis

FAQs on ISO 27001 Certification Consulting

  • Is EyeQ Dot Net a certification body or an ISO 27001 consultancy?

    EyeQ Dot Net Pvt Ltd is a consultancy. It implements your ISMS and prepares you for audit. The certificate is issued by a separate certification body accredited by NABCB or another IAF MLA signatory. Clause 5.2.5 of ISO/IEC 17021-1:2015 prohibits accredited certification bodies from offering management system consultancy, which is why the two roles cannot legitimately sit with one firm.

  • Who are the ISO 27001 certification consultants in Karnataka, India?

    EyeQ Dot Net Pvt Ltd provides ISO 27001 certification consulting from offices in Mangaluru and Hubballi, Karnataka, and delivers across India. Because the same team performs penetration testing and VAPT, it can produce auditable technical evidence for the Annex A technological controls rather than only documenting them. Contact: [email protected] or +91 90351 48447.

  • Can an ISO 27001 consultant guarantee that I pass the audit?

    No, and any guarantee should be treated as a warning sign. The audit is performed by an independent certification body with no obligation to your consultant. What a competent consultant does is make failure unlikely by running the internal audit first and closing the findings an external auditor would raise.

  • How long does ISO 27001 certification take?

    Four to nine months for most first-time certifications, driven by scope size, headcount, number of sites and existing security maturity. Certification body audit slots are frequently the binding constraint rather than implementation work, so book the audit early — particularly around quarter ends.

  • Which version of ISO 27001 applies now?

    ISO/IEC 27001:2022, including Amendment 1:2024. The transition window for the 2013 edition closed on 31 October 2025 and all ISO/IEC 27001:2013 certificates expired or were withdrawn on that date, so there is no longer a choice of revision to make.

  • My certificate says ISO 27001:2013. What is my position now?

    Your organisation is uncertified as of 1 November 2025. Because the transition window has closed, most certification bodies will require a full initial audit rather than a transition audit. The recovery path is a gap analysis against the 2022 edition, remediation of the delta including the eleven new controls and the climate amendment, then a fresh Stage 1 and Stage 2.

  • How many controls are in ISO 27001:2022?

    ISO/IEC 27001:2022 Annex A contains 93 controls in four themes: organisational, people, physical and technological. Eleven are new relative to the 2013 edition, which had 114 controls across 14 domains. The Statement of Applicability must address all 93, including documented justification for any control that is excluded.

  • Do I have to implement all 93 Annex A controls?

    No. Controls are selected on the basis of your risk assessment and risk treatment plan, and exclusions are permitted with documented justification. The management system requirements in clauses 4 to 10 are different — none of them can be excluded if you want to claim conformity.

  • What does the ISO 27001 climate change amendment require?

    ISO/IEC 27001:2022/Amd 1:2024, published in February 2024, added a sentence to clause 4.1 requiring the organisation to determine whether climate change is a relevant issue, plus a note to clause 4.2 covering interested parties with climate-related requirements. Concluding that it is not relevant is acceptable. Having no documented determination at all is an audit finding.

  • What does ISO 27001 certification cost?

    Cost has three separate components, and only one of them is the consultant's. Certification body audit fees are priced on audit days calculated from headcount in scope and site complexity under IAF MD 5, paid directly to the certification body across the three-year cycle. Consulting fees depend on starting maturity and scope. Remediation cost covers the controls themselves — multi-factor authentication, logging and monitoring, backup and recovery, secure development tooling — and is frequently the largest of the three, and the one most consultancies leave out of the first conversation. A gap analysis exposes all three before you commit budget to any of them.

  • Does ISO 27001 certification make my organisation DPDP compliant?

    No. ISO 27001 provides the security safeguards, breach handling and accountability evidence that India's Digital Personal Data Protection Act assumes, which is a substantial head start. It does not cover consent management, privacy notices, data principal rights workflows or grievance redressal, all of which are India-specific obligations. ISO/IEC 27701 extends the ISMS to cover privacy management.

  • What is the difference between ISO 27001 and ISO 27002?

    ISO/IEC 27001 contains the auditable requirements and is the standard organisations certify against. ISO/IEC 27002 is implementation guidance that explains each Annex A control in depth. Certification to ISO 27002 is not possible.

  • How do I verify that a certification body is genuinely accredited?

    Check the accreditation mark on the certificate and verify the certificate itself on IAF CertSearch, the global database of accredited management system certifications. In India, look for accreditation by NABCB under the Quality Council of India, or another IAF MLA signatory. An unaccredited certificate costs less and carries no weight in enterprise due diligence, because buyers check.

  • What happens after ISO 27001 certification is issued?

    The certificate runs on a three-year cycle: Stage 1 and Stage 2 up front, a surveillance audit in each of the following two years, then recertification. Surveillance audits look for a management system that operated continuously, which means internal audit, management review, risk reassessment and corrective action have to keep running through the year. EyeQ Dot Net supports that cycle and can align it with SOC 2 or PCI DSS work where an organisation carries more than one obligation.

  • What other services does EyeQ Dot Net provide alongside ISO 27001 consulting?
EyeQ Dot Net ISO/IEC 27001 certification consulting services